A flaw was found in org.keycloak.broker.saml. When a disabled Security Assertion Markup Language (SAML) client is configured as an Identity Provider (IdP)-initiated broker landing target, it can still complete the login process and establish a Single Sign-On (SSO) session. This allows a remote attacker to gain unauthorized access to other enabled clients without re-authentication, effectively bypassing security restrictions.
rhbk/keycloak Red Hat / RHEL
Fixed in: rhel9@sha256:172d9f060709fdf5df5b6a8db9dc8001ff4d41025900e225d43ded8d189522d6_ppc64le RHSA-2026:3925 Fixed in: rhel9-operator@sha256:6dead5fff17a33fc1e37a28f98051f631a74b616d0a2d66fe84169d0eeaed0b4_ppc64le RHSA-2026:3925 Fixed in: rhel9@sha256:708b0282101911143c468a7c78a3c815e8a8fcee01d001d1e9504d7fa14c9337_arm64 RHSA-2026:3925 Fixed in: rhel9-operator@sha256:252532cad9e091df87b895d82a59dfb6bc7bc97a777fe313ca43f0cacee7bd10_arm64 RHSA-2026:3925 Fixed in: rhel9@sha256:08b5b94d827dbdaba29126c9389476341d1ca9ebeca6a764491862a38d19bb0e_s390x RHSA-2026:3925 Fixed in: rhel9-operator@sha256:cb02cd23c13e0ae1e6404784b22608444b0752749432970ad1e8c4f2cd74ea53_s390x RHSA-2026:3925 Fixed in: rhel9@sha256:97f579e9720a458a3d4a277dd19cc0e669b70bf863fdda5298f420d6442dd199_amd64 RHSA-2026:3925 Fixed in: operator-bundle@sha256:ca0959572305bc27cc969355f06e14b0bb5c7dedea9619e884f7bd3bec9bb2bc_amd64 RHSA-2026:3925 Fixed in: rhel9-operator@sha256:c1664981fec90044019cc72cd634f7d1568e9ca906bce2c6365dfa548ac88122_amd64 RHSA-2026:3925 Fixed in: rhel9@sha256:884c31d8ddfd03349a65bc76851cdf83d7cf8db0983e9e8c52a648298cd8c7eb_amd64 RHSA-2026:3948 Fixed in: operator-bundle@sha256:ae13f29ccde0ddf5d96d14567177fcdfa2dd12cb29ca7793b47c857436d2a3e8_amd64 RHSA-2026:3948 Fixed in: rhel9-operator@sha256:adc45a57c1cc6f816e6c0074cd9aeba6c6b323a0c708d5d11678bb49af578a6a_amd64 RHSA-2026:3948 Fixed in: rhel9@sha256:b0efe038b71e19b53e41ccede51fefcd03d81e2aafd6fa0b23b5b9c8dac212fd_s390x RHSA-2026:3948 Fixed in: rhel9-operator@sha256:cbb01b2cdd4857eddc5c94a1382c11901883d0df6176593a099d01791f6b72bf_s390x RHSA-2026:3948 Fixed in: rhel9@sha256:48fa03e7e881b996085a2207878c6ab610fa770fbedf41f195d270aefb8bf9f7_arm64 RHSA-2026:3948 Fixed in: rhel9-operator@sha256:2ff84fdf2ccf5ef7fb360d0b33b7369ae948b7eba84926320431adb1da23d9a7_arm64 RHSA-2026:3948 Fixed in: rhel9@sha256:73cf1a2410318ef2e508c21dc5c3332d3f3658eaab7d9b0e4dadfb570c002899_ppc64le RHSA-2026:3948 Fixed in: rhel9-operator@sha256:edeb162dfffdcaf118c3fa7b951a563de58a88b4604764c8651396056e6ba814_ppc64le RHSA-2026:3948 rhbk/keycloak Rocky
Fixed in: rhel9@sha256:172d9f060709fdf5df5b6a8db9dc8001ff4d41025900e225d43ded8d189522d6_ppc64le RHSA-2026:3925 Fixed in: rhel9-operator@sha256:6dead5fff17a33fc1e37a28f98051f631a74b616d0a2d66fe84169d0eeaed0b4_ppc64le RHSA-2026:3925 Fixed in: rhel9@sha256:708b0282101911143c468a7c78a3c815e8a8fcee01d001d1e9504d7fa14c9337_arm64 RHSA-2026:3925 Fixed in: rhel9-operator@sha256:252532cad9e091df87b895d82a59dfb6bc7bc97a777fe313ca43f0cacee7bd10_arm64 RHSA-2026:3925 Fixed in: rhel9@sha256:08b5b94d827dbdaba29126c9389476341d1ca9ebeca6a764491862a38d19bb0e_s390x RHSA-2026:3925 Fixed in: rhel9-operator@sha256:cb02cd23c13e0ae1e6404784b22608444b0752749432970ad1e8c4f2cd74ea53_s390x RHSA-2026:3925 Fixed in: rhel9@sha256:97f579e9720a458a3d4a277dd19cc0e669b70bf863fdda5298f420d6442dd199_amd64 RHSA-2026:3925 Fixed in: operator-bundle@sha256:ca0959572305bc27cc969355f06e14b0bb5c7dedea9619e884f7bd3bec9bb2bc_amd64 RHSA-2026:3925 Fixed in: rhel9-operator@sha256:c1664981fec90044019cc72cd634f7d1568e9ca906bce2c6365dfa548ac88122_amd64 RHSA-2026:3925 Fixed in: rhel9@sha256:884c31d8ddfd03349a65bc76851cdf83d7cf8db0983e9e8c52a648298cd8c7eb_amd64 RHSA-2026:3948 Fixed in: operator-bundle@sha256:ae13f29ccde0ddf5d96d14567177fcdfa2dd12cb29ca7793b47c857436d2a3e8_amd64 RHSA-2026:3948 Fixed in: rhel9-operator@sha256:adc45a57c1cc6f816e6c0074cd9aeba6c6b323a0c708d5d11678bb49af578a6a_amd64 RHSA-2026:3948 Fixed in: rhel9@sha256:b0efe038b71e19b53e41ccede51fefcd03d81e2aafd6fa0b23b5b9c8dac212fd_s390x RHSA-2026:3948 Fixed in: rhel9-operator@sha256:cbb01b2cdd4857eddc5c94a1382c11901883d0df6176593a099d01791f6b72bf_s390x RHSA-2026:3948 Fixed in: rhel9@sha256:48fa03e7e881b996085a2207878c6ab610fa770fbedf41f195d270aefb8bf9f7_arm64 RHSA-2026:3948 Fixed in: rhel9-operator@sha256:2ff84fdf2ccf5ef7fb360d0b33b7369ae948b7eba84926320431adb1da23d9a7_arm64 RHSA-2026:3948 Fixed in: rhel9@sha256:73cf1a2410318ef2e508c21dc5c3332d3f3658eaab7d9b0e4dadfb570c002899_ppc64le RHSA-2026:3948 Fixed in: rhel9-operator@sha256:edeb162dfffdcaf118c3fa7b951a563de58a88b4604764c8651396056e6ba814_ppc64le RHSA-2026:3948 TridentStack Control can deploy fixes like this automatically across your Windows, macOS, and Linux fleet. See how it works
Remediation is compiled from vendor and distribution security advisories. Always confirm against the linked source for your exact version and platform.
Exploitability
Attack Vector Network
Attack Complexity Low
Privileges Required Low
User Interaction None
Scope Unchanged
Impact
Confidentiality High
Integrity High
Availability High
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
0.47% probability of exploitation in 30 days
38th percentile
Low risk: more likely to be exploited than 38% of all known CVEs.
Other CWE-305 vulnerabilities, ordered by exploit likelihood. View all
Embed a live status badge for CVE-2026-3047 Markdown
[](https://tridentstack.com/cve/CVE-2026-3047)HTML
<a href="https://tridentstack.com/cve/CVE-2026-3047"><img src="https://tridentstack.com/cve/badge/CVE-2026-3047.svg" alt="CVE-2026-3047"></a>Find and fix vulnerabilities across your fleet TridentStack Control continuously scans your Windows, macOS, and Linux fleet for known vulnerabilities, prioritizes them by severity and active exploitation, and patches them automatically.
This product uses NVD data but is not endorsed or certified by the NVD. EPSS scores courtesy of FIRST.org (https://www.first.org/epss). Source: CISA KEV Catalog. Data as of 2026-07-15.